CVE-2015-5757
- EPSS 1.08%
- Veröffentlicht 17.08.2015 00:00:39
- Zuletzt bearbeitet 12.04.2025 10:46:40
libpthread in Apple iOS before 8.4.1 and OS X before 10.10.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via an app that uses a crafted syscall to interfere with locking.
CVE-2015-5756
- EPSS 2.1%
- Veröffentlicht 17.08.2015 00:00:38
- Zuletzt bearbeitet 12.04.2025 10:46:40
FontParser in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted font file, a different vulnerability than CVE-2015-380...
CVE-2015-5755
- EPSS 2.81%
- Veröffentlicht 17.08.2015 00:00:36
- Zuletzt bearbeitet 12.04.2025 10:46:40
CoreText in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted font file, a different vulnerability than CVE-2015-5761.
- EPSS 0.43%
- Veröffentlicht 17.08.2015 00:00:32
- Zuletzt bearbeitet 12.04.2025 10:46:40
Backup in Apple iOS before 8.4.1 allows attackers to bypass intended restrictions on filesystem access via a crafted app that creates a symlink.
CVE-2015-5749
- EPSS 0.3%
- Veröffentlicht 17.08.2015 00:00:28
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Sandbox_profiles component in Apple iOS before 8.4.1 allows attackers to bypass the third-party app-sandbox protection mechanism and read arbitrary managed preferences via a crafted app.
CVE-2015-5748
- EPSS 0.08%
- Veröffentlicht 17.08.2015 00:00:27
- Zuletzt bearbeitet 12.04.2025 10:46:40
The kernel in Apple OS X before 10.10.5 does not properly mount HFS volumes, which allows local users to cause a denial of service via a crafted volume.
- EPSS 0.23%
- Veröffentlicht 17.08.2015 00:00:24
- Zuletzt bearbeitet 12.04.2025 10:46:40
AppleFileConduit in Apple iOS before 8.4.1 allows attackers to bypass intended restrictions on filesystem access via an afc command that leverages symlink mishandling.
CVE-2015-3807
- EPSS 2.37%
- Veröffentlicht 17.08.2015 00:00:22
- Zuletzt bearbeitet 12.04.2025 10:46:40
libxml2 in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (memory corruption) via a crafted XML document.
CVE-2015-3806
- EPSS 0.05%
- Veröffentlicht 17.08.2015 00:00:21
- Zuletzt bearbeitet 12.04.2025 10:46:40
Apple iOS before 8.4.1 and OS X before 10.10.5 allow local users to bypass a code-signing protection mechanism by appending code to a crafted executable file.
CVE-2015-3805
- EPSS 0.06%
- Veröffentlicht 17.08.2015 00:00:19
- Zuletzt bearbeitet 12.04.2025 10:46:40
Apple iOS before 8.4.1 and OS X before 10.10.5 allow local users to bypass a code-signing protection mechanism via a crafted Mach-O file, a different vulnerability than CVE-2015-3802.